CVE-2015-9340: Malicious File Upload
Published Aug 22, 2019
·Updated
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
Affected Software
1 affected component
Iptanus Wordpress File Upload Wordpress<3.0.0
Event History
Aug 22, 2019
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9340?
CVE-2015-9340 is a vulnerability in the wp-file-upload plugin for WordPress that allows for the unrestricted upload of certain file types.
2
What is the severity of CVE-2015-9340?
CVE-2015-9340 has a severity value of 7.5, which is considered high.
3
Which files are affected by CVE-2015-9340?
CVE-2015-9340 affects php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
4
How can I fix CVE-2015-9340?
To fix CVE-2015-9340, update the wp-file-upload plugin to version 3.0.0 or higher.
5
Where can I find more information about CVE-2015-9340?
More information about CVE-2015-9340 can be found at the following link: [https://wordpress.org/plugins/wp-file-upload/#developers](https://wordpress.org/plugins/wp-file-upload/#developers).